zizmor
Static analysis for GitHub Actions.
zizmor is a static analysis tool for GitHub Actions. It can find many common security issues in typical GitHub Actions CI/CD setups, including: - Template injection vulnerabilities, leading to attacker-controlled code execution - Accidental credential persistence and leakage - Excessive permission scopes and credential grants to runners - Impostor commits and confusable git references - ...and much more!
winget install --id zizmor.zizmor --exact --source wingetLatest 1.30.1·September 9, 2026
Details
- Homepage
- https://zizmor.sh/
- License
- MIT
- Publisher
- William Woodruff
- Support
- https://github.com/zizmorcore/zizmor/issues
- Copyright
- Copyright (c) 2024 William Woodruff <william @ yossarian.net>